Release date:
2026-08-27 09:28:34 UTC
Description:
* SECURITY UPDATE: Authorization bypass through collisions between user
fields and system metadata
- debian/patches/CVE-2026-9750.patch: keep user-supplied metadata field
names separate from system-injected document metadata
- CVE-2026-9750
* SECURITY UPDATE: Denial of service through nested BSONColumn values
- debian/patches/CVE-2026-9740.patch: reject BSONColumn values nested in
literal or interleaved BSONColumn content
- CVE-2026-9740
* SECURITY UPDATE: Sensitive server parameter values exposed in logs
- debian/patches/CVE-2026-9751.patch: force redaction of parameters marked
sensitive in setParameter log messages
- CVE-2026-9751
* SECURITY UPDATE: Authorization bypass through a race in killCursors
- debian/patches/CVE-2025-13643.patch: recheck cursor ownership while
holding the cursor manager lock before killing a cursor
- CVE-2025-13643
Updated packages:
-
mongodb6_6.0.26-1+tuxcare.els18_amd64.deb
sha:bbf464e064b50a7e5fa58cb7c061cb7a7f6095b0
-
mongodb6-mongos_6.0.26-1+tuxcare.els18_amd64.deb
sha:a736544b873982df96ece8af4a17b5cb7e83c797
-
mongodb6-server_6.0.26-1+tuxcare.els18_amd64.deb
sha:f96c98237d414bf5929e205adc776cee55e576a7
-
mongodb6-shell_6.0.26-1+tuxcare.els18_amd64.deb
sha:c159e9c2f22c95b6798c8383a05ed1abae83a696
-
mongodb6_6.0.26-1+tuxcare.els18_arm64.deb
sha:3d07f7d5d068f33a713b7dfa9762d4a295174520
-
mongodb6-mongos_6.0.26-1+tuxcare.els18_arm64.deb
sha:3504061b4365c7702b17a219759286ccd323a473
-
mongodb6-server_6.0.26-1+tuxcare.els18_arm64.deb
sha:8d555f069adf34691aac0a87d86de145abace2d4
-
mongodb6-shell_6.0.26-1+tuxcare.els18_arm64.deb
sha:9cf572e384428fe634c7195c8074ed79d1ce7d99
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.